SQL Injection Vulnerability in Microsoft SQL Server
CVE-2026-26116
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-26116?
A vulnerability exists in Microsoft SQL Server that allows an authorized attacker to perform an SQL injection. This could enable the attacker to execute arbitrary SQL commands, potentially leading to elevated privileges over the network, thus compromising the security of the database and sensitive data within. Users are encouraged to apply the latest security patches to mitigate this risk.
Affected Version(s)
Microsoft SQL Server 2025 (CU 2) x64-based Systems 17.0.0.0 < 17.0.4020.2
Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.0.1050.2 < 17.0.1105.2